ClipXDaemon: X11 Clipboard Hijacker Via Bincrypter
ID: b26760be-01f7-5f10-8ff0-3f2154d5fd7e
STIX ID: report--b26760be-01f7-5f10-8ff0-3f2154d5fd7e
Feed Name: Cyble Blog
Threat Score
**ClipXDaemon — Autonomous X11 Clipboard Hijacker:** This report analyzes ClipXDaemon, a Linux userland malware that is staged via a bincrypter-generated in-memory loader and dropper, persists via ~/.profile, daemonizes and masquerades as a kernel worker, polls the X11 clipboard every ~200ms, and replaces matched cryptocurrency addresses with attacker-controlled wallets entirely offline (no C2).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
